Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

mukarillo

[Resolvido!] Suspeita de vírus

Recommended Posts

Olá galera, hoje a tarde, derrepente, meu msn começou a abrir inúmeras janelas de converça e chamar a atenção e mandar umas mensagens que nao tem nada a ve ( tipo: SQA$#), támbem abria o site do msn. ai procurei na internet e achei o site de você's não sei bem o que fazer, lendo umas instruções ai eu vi um tal de HijackThis e fiz.

 

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\dlllhost.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\3nvy\alg.exe

C:\svrhost.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\dwwin.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PSIService.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\dlllhost.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

 

--

End of file - 5054 bytes

 

 

Caso eu tenha de fazer outra coisa, porfavor me falem :/

to com medo de ser um keyloger ou algo parecido!

 

Valeu,

Muka.

 

Ps: Meu computador, abre uma janela falando qeu deu um erro no Explorer.exe. Alguem sabe arrumar isso :s Obrigado denovo

 

Edit: quando eu instalei o avast! ele diz qeu tem um vírus na memoria RAM e que precisa ser reiniciado para qeu possa fazer uma verificação ( algo assim). O que devo fazer?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! mukarillo

 

<!> Seu relatório do HijackThis,veio sem o cabeçalho.

<><><><><><><><><><><>

<@> Baixe: < marcinsig.gif >

 

<@> < Link - 2 >

 

<@> < Link - 3 >

 

<@> Atualize o programa!

<@> Escolha o escaneamento Completo!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

<><><><><><><><><><><>

<@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Malwarebytes' Anti-Malware 1.42

Versão do banco de dados: 3350

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

 

12/12/2009 22:41:54

mbam-log-2009-12-12 (22-41-54).txt

 

Tipo de Verificação: Completa (C:\|D:\|E:\|)

Objetos verificados: 227322

Tempo decorrido: 32 minute(s), 42 second(s)

 

Processos da Memória infectados: 1

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 3

Valores do Registro infectados: 0

Ítens do Registro infectados: 3

Pastas infectadas: 2

Arquivos infectados: 8

 

Processos da Memória infectados:

C:\WINDOWS\system32\dlllhost.exe (Worm.AutoRun) -> Unloaded process successfully.

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Worm.AutoRun) -> Data: c:\windows\system32\dlllhost.exe -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Worm.AutoRun) -> Data: system32\dlllhost.exe -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\dlllhost.exe) Good: (Userinit.exe) -> Quarantined and deleted successfully.

 

Pastas infectadas:

C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013 (Backdoor.IRCBot) -> Quarantined and deleted successfully.

C:\WINDOWS\3nvy (Trojan.Banker) -> Quarantined and deleted successfully.

 

Arquivos infectados:

C:\WINDOWS\system32\dlllhost.exe (Worm.AutoRun) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\iexplorer.pif (Backdoor.Bot) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\s3tu7.dll (Backdoor.Bot) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\tum8v.exe (HackTool.PWSViewer) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{584F9A72-8980-4029-9F43-668B28870040}\RP67\A0028370.exe (Backdoor.IRCbot) -> Quarantined and deleted successfully.

C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Backdoor.IRCBot) -> Quarantined and deleted successfully.

C:\WINDOWS\3nvy\alg.ex (Trojan.Banker) -> Quarantined and deleted successfully.

C:\Arquivos de programas\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.

 

 

 

E o do HijackThis

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:47:08, on 12/12/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PSIService.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

 

--

End of file - 5238 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! mukarillo

 

<@> Baixe: < desktopicon.png > ( ...by sUBs )

 

<!> Link-2 --> < ForoSpyware >

 

<!> Link-3 --> < GeeksToGo >

 

<!> Link-4 --> < como usar o combofix >

 

<@> Salve-o no desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

 

<@> Ps: A execução,por comando,também é possível:

<@> Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\Combofix.exe" /killall

 

combofixejr8.gif

 

<@> Clique em Ok.

<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!

 

RcAuto1.gif

 

<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

<@> Terminando,clique Sim ou Yes. --> Aguarde!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta ComboFix.exe e faça,novamente,seu download.

<!> Salve-a no desktop,renomeada como: Kombo.exe

<!> Ps: Nomeie durante o salvamento,e não após salvá-la!

<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em "Modo de Segurança". <-- Link!

<!> Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação:

 

Rookit_found.gif

 

<!> Ps: Anote essas detecções,e dê o OK.

<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

<!> Ps: Evite executar,voluntariamente,esta ferramenta!

<!> Ps: Para evitar problemas,siga todas as recomendações propostas.

<!> nuke.gifO ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional.

<@> Abrir-se-á a janela Auto Scan. --> Aguarde!

<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!

<><><><><><><><><><><><>

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

aqui esta o log do Combo

 

ComboFix 09-12-11.05 - Lopes 13/12/2009 3:08.1.4 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.2559.1961 [GMT -2:00]

Executando de: c:\documents and settings\Lopes\desktop\Combofix.exe

Comandos utilizados :: /killall

AV: avast! antivirus 4.8.1368 [VPS 091212-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}

FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

 

ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\recycler\S-1-5-21-1123561945-1960408961-682003330-1001

C:\restore

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-11-13 to 2009-12-13 ))))))))))))))))))))))))))))

.

 

2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Malwarebytes

2009-12-13 00:07 . 2009-12-03 18:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Malwarebytes

2009-12-13 00:07 . 2009-12-03 18:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-12 23:05 . 2009-12-13 04:53 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat

2009-12-12 22:33 . 2009-12-12 23:05 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Comodo

2009-12-12 22:33 . 2009-12-12 22:33 87104 ----a-w- c:\windows\system32\drivers\inspect.sys

2009-12-12 22:33 . 2009-12-12 22:33 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2009-12-12 22:33 . 2009-12-12 22:33 171552 ----a-w- c:\windows\system32\guard32.dll

2009-12-12 22:33 . 2009-12-12 22:33 133064 ----a-w- c:\windows\system32\drivers\cmdguard.sys

2009-12-12 22:33 . 2009-12-12 22:33 -------- d-----w- c:\arquivos de programas\COMODO

2009-12-12 22:14 . 2009-12-12 22:15 -------- d-----w- C:\LinhaDefensiva

2009-12-12 21:36 . 2009-12-12 22:17 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Spybot - Search & Destroy

2009-12-12 21:36 . 2009-12-12 21:36 -------- d-----w- c:\arquivos de programas\Spybot - Search & Destroy

2009-12-12 21:30 . 2009-12-12 21:30 -------- d-----w- c:\arquivos de programas\CCleaner

2009-12-12 21:17 . 2009-12-12 21:45 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Symantec Shared

2009-12-12 21:05 . 2009-12-12 21:07 707329 ----a-w- C:\Wanasah.exe

2009-12-12 16:22 . 2009-12-12 21:25 2771 ----a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys

2009-12-12 00:37 . 2009-12-12 00:37 53248 ----a-w- c:\windows\fullscreen.exe

2009-12-06 17:33 . 2009-12-06 17:33 -------- d-----w- c:\arquivos de programas\ElfBot NG852

2009-12-05 23:56 . 2009-12-05 23:56 -------- d-----w- c:\windows\system32\LogFiles

2009-12-04 11:31 . 2009-12-04 12:16 -------- d-----w- c:\arquivos de programas\tibiacast2

2009-12-04 11:26 . 2009-11-06 14:49 551936 ----a-w- c:\arquivos de programas\Tibiacast Installer.msi

2009-12-04 11:26 . 2009-12-04 11:23 507461 ----a-w- c:\arquivos de programas\tibiacast_2_6_1.zip

2009-12-03 03:08 . 2009-08-19 07:18 107864 ----a-w- c:\windows\system32\tsccvid.dll

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\windows\system32\QuickTime

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\QuickTime

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\Arquivos comuns\TechSmith Shared

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\TechSmith

2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Publish Providers

2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Sony

2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Vstplugins

2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Sony

2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Sony

2009-12-03 02:53 . 2009-12-03 02:53 -------- d-----w- c:\arquivos de programas\Sony Setup

2009-12-02 20:54 . 2008-07-08 17:29 1654869 ----a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\DynuEncrypt.dll

2009-12-02 19:30 . 2009-12-02 19:30 -------- d-----w- C:\Level Up! Games

2009-12-02 19:21 . 2009-12-02 19:21 -------- d-----w- C:\TopGames37

2009-12-02 19:18 . 2009-12-02 19:18 -------- d-----w- c:\arquivos de programas\Arquivos comuns\SWF Studio

2009-11-28 13:20 . 2009-11-28 13:21 -------- d-----w- c:\arquivos de programas\TibiaCam TV Lite

2009-11-27 16:07 . 2009-11-27 16:07 -------- d-----w- c:\arquivos de programas\Tibia850

2009-11-26 01:43 . 2009-11-26 01:43 -------- d-----w- c:\arquivos de programas\Gravity

2009-11-26 00:53 . 2009-02-09 05:10 67208 ----a-w- c:\windows\UnDeploy.exe

2009-11-26 00:49 . 2009-11-26 00:50 -------- d-----w- c:\windows\system32\NtmsData

2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Norton

2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Symantec

2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\arquivos de programas\NortonInstaller

2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\NortonInstaller

2009-11-24 19:51 . 2009-11-24 19:51 -------- d-----w- c:\windows\system32\Adobe

2009-11-23 22:34 . 2009-11-23 22:34 -------- d-----w- c:\arquivos de programas\Windows Journal Viewer

2009-11-18 00:43 . 2009-11-18 00:43 190464 ----a-w- c:\windows\system32\delzip179.dll

2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Eng.dll

2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Kor.dll

2009-11-15 22:57 . 2009-09-23 19:42 364912 ----a-w- c:\windows\system32\CMStarterCore.exe

2009-11-15 22:54 . 2009-11-15 22:57 -------- d-----w- c:\arquivos de programas\Webzen

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-13 05:07 . 2009-10-18 20:35 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\TEMP

2009-12-12 22:19 . 2009-09-06 22:27 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Tibia

2009-12-11 13:49 . 2009-09-06 22:26 -------- d-----w- c:\arquivos de programas\Tibia

2009-12-09 23:24 . 2009-10-18 20:34 -------- d-----w- c:\arquivos de programas\ElfBot NG

2009-12-08 22:56 . 2009-09-07 04:33 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center

2009-12-02 19:14 . 2009-09-05 22:28 -------- d-----w- c:\arquivos de programas\microsoft frontpage

2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Media Player Classic

2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack

2009-11-29 16:05 . 2009-09-11 23:43 -------- d-----w- c:\arquivos de programas\Teamspeak2_RC2

2009-11-24 23:54 . 2009-09-07 00:38 1280480 ----a-w- c:\windows\system32\aswBoot.exe

2009-11-24 23:51 . 2009-09-07 00:38 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys

2009-11-24 23:50 . 2009-09-07 00:38 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2009-11-24 23:50 . 2009-09-07 00:38 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys

2009-11-24 23:50 . 2009-09-07 00:38 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2009-11-24 23:49 . 2009-09-07 00:38 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2009-11-24 23:48 . 2009-09-07 00:38 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2009-11-24 23:47 . 2009-09-07 00:38 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2009-11-24 23:47 . 2009-09-07 00:38 97480 ----a-w- c:\windows\system32\AvastSS.scr

2009-11-16 20:58 . 2009-09-07 00:30 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys

2009-11-15 22:57 . 2009-09-05 22:36 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information

2009-11-09 19:29 . 2009-11-09 19:27 -------- d-----w- c:\arquivos de programas\Tibia852

2009-11-09 18:00 . 2009-11-29 20:50 85504 ----a-w- c:\windows\system32\ff_vfw.dll

2009-11-08 22:21 . 2009-11-08 22:10 -------- d-----w- c:\arquivos de programas\No-IP

2009-11-02 13:49 . 2009-11-02 13:49 -------- d-----w- c:\arquivos de programas\Asprate

2009-10-31 22:20 . 2009-09-10 23:36 -------- d-----w- c:\arquivos de programas\TibiaTestserver

2009-10-18 13:34 . 2003-03-30 14:06 76196 ----a-w- c:\windows\system32\perfc016.dat

2009-10-18 13:34 . 2003-03-30 14:06 465632 ----a-w- c:\windows\system32\perfh016.dat

2009-10-06 23:56 . 2009-10-04 01:51 415526 ----a-w- c:\arquivos de programas\backgroung.bmp

2009-09-07 00:30 . 2009-09-07 00:30 8 --sh--r- c:\windows\system32\EBE27D3236.sys

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]

"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-21 13680640]

"COMODO Internet Security"="c:\arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" [2009-12-12 1800464]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\system32\guard32.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk]

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Microsoft Office.lnk

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2008-10-15 04:04 39792 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2008-06-19 08:20 57344 ----a-r- c:\windows\ALCMTR.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]

2007-08-17 14:50 483144 ----a-w- c:\arquivos de programas\Corel\Corel MediaOne\Corel Photo Downloader.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2004-08-04 03:45 15360 ------w- c:\windows\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-08-04 03:56 1667584 ------w- c:\arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

2009-01-21 16:08 13680640 ----a-w- c:\windows\system32\nvcpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

2009-01-21 16:08 86016 ----a-w- c:\windows\system32\nvmctray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2009-01-21 16:08 1657376 ----a-w- c:\windows\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2008-11-17 08:08 17676288 ----a-r- c:\windows\RTHDCPL.EXE

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Tibia\\Tibia.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"c:\\Arquivos de programas\\Valve\\hl.exe"=

"c:\\Arquivos de programas\\Tibia852\\Tibia.exe"=

"c:\\Arquivos de programas\\Tibia850\\Tibia.exe"=

"c:\\Arquivos de programas\\Tibia\\Tibia2.exe"=

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/9/2009 22:38 114768]

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [12/12/2009 20:33 133064]

R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/12/2009 20:33 25160]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/9/2009 22:38 20560]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.terra.com.br/portal/

uInternet Connection Wizard,ShellNext = iexplore

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office10\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=3&q={searchTerms}

FF - prefs.js: browser.startup.homepage - www.google.com

FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=2&q=

FF - component: c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\extensions\{41fe951c-2aaf-4f08-ab67-aebd1ed636f2}\components\FFExternalAlert.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

- - - - ORFÃOS REMOVIDOS - - - -

 

AddRemove-ms32 - c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\iexplorer.pif

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-13 03:13

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(4040)

c:\windows\system32\msi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

c:\arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

c:\arquivos de programas\Alwil Software\Avast4\ashServ.exe

c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\PSIService.exe

c:\arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

c:\arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-12-13 03:16:08 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-12-13 05:16

 

Pré-execução: 10 pasta(s) 376.206.114.816 bytes disponíveis

Pós execução: 12 pasta(s) 376.184.508.416 bytes disponíveis

 

- - End Of File - - 64CDB4A10B1209AD4C3882833B1EE3B6

 

 

E aqui do HijackThis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 03:18:43, on 13/12/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PSIService.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

 

--

End of file - 4927 bytes

 

 

Obrigado desde já!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! mukarillo

 

<!> Você possui 2 antivírus: Comodo e Avast

<!> Faça a opção por um deles e,se escolher o Comodo,desinstale o Spybot.

<!> Ps: Caso desinstale o Comodo,faça-o em Modo de Segurança.

<><><><><><><><><><><>

<@> Desinstale o Malwarebytes.

<@> Dê um duplo-clique no arquivo em destaque:

 

<!> C:\Arquivos de programas\Malwarebytes' Anti-Malware\unins000.exe <--

 

<@> Reinicie o computador,após a conclusão!

<><><><><><><><><><><>

<@> Selecione e copie,todo o conteúdo que está na área do Quote,para o Bloco de Notas.

<@> Salve-o,no desktop,com o nome: CFScript.txt

 

File::

c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys

c:\windows\system32\EBE27D3236.sys

Driver::

"npggsvc"

"EBE27D3236"

Folder::

c:\arquivos de programas\Arquivos comuns\Symantec Shared

C:\LinhaDefensiva

<@> Ps: Não utilizem este script em outra máquina!

<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.

<@> Veja a demonstração!

 

2872959479_997d4500c4_o.gif

 

<@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix.

<@> Ps: Faça o arraste,até surgir essa solicitação! ( janela )

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui vai do Combo

 

ComboFix 09-12-11.05 - Lopes 13/12/2009 13:13:55.2.4 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.2559.2066 [GMT -2:00]

Executando de: c:\documents and settings\Lopes\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Lopes\Desktop\CFScript.txt

AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}

FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

 

FILE ::

"c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys"

"c:\windows\system32\EBE27D3236.sys"

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\arquivos de programas\Arquivos comuns\Symantec Shared

c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys

C:\LinhaDefensiva

c:\linhadefensiva\banker.bat

c:\linhadefensiva\BankerFix.vbs

c:\linhadefensiva\credits\exec.txt

c:\linhadefensiva\exec\download.exe

c:\linhadefensiva\exec\md5.exe

c:\linhadefensiva\exec\MoveEx.exe

c:\linhadefensiva\exec\pv.exe

c:\linhadefensiva\exec\unzip.exe

c:\linhadefensiva\func\lang.vbs

c:\linhadefensiva\func\reg.vbs

c:\linhadefensiva\func\scan.vbs

c:\linhadefensiva\func\strings.vbs

c:\linhadefensiva\Iniciar-BankerFix.vbs

c:\linhadefensiva\lang\bat\antivirusnote.txt

c:\linhadefensiva\lang\bat\changepass.txt

c:\linhadefensiva\lang\bat\error-removing.txt

c:\linhadefensiva\lang\bat\filesremoved.txt

c:\linhadefensiva\lang\bat\logend.txt

c:\linhadefensiva\lang\bat\logremhelp.txt

c:\linhadefensiva\lang\bat\logremtif.txt

c:\linhadefensiva\lang\bat\noproblems.txt

c:\linhadefensiva\lang\bat\opening.txt

c:\linhadefensiva\lang\bat\rebootrequired.txt

c:\linhadefensiva\lang\bat\seeforum.txt

c:\linhadefensiva\lang\bat\wait.txt

c:\linhadefensiva\lang\bat\win95.txt

c:\linhadefensiva\lang\init\en.txt

c:\linhadefensiva\lang\init\ptb.txt

c:\linhadefensiva\lang\vb\bankerfix.txt

c:\linhadefensiva\lang\vb\loader.txt

c:\linhadefensiva\lang\vb\postreboot.txt

c:\linhadefensiva\leiame.txt

c:\linhadefensiva\QUA\backup.reg

c:\linhadefensiva\readme.txt

c:\linhadefensiva\reflist\fx.reg

c:\linhadefensiva\reflist\ref-allu

c:\linhadefensiva\reflist\ref-appdata

c:\linhadefensiva\reflist\ref-commonfiles

c:\linhadefensiva\reflist\ref-hosts

c:\linhadefensiva\reflist\ref-md5

c:\linhadefensiva\reflist\ref-mydoc

c:\linhadefensiva\reflist\ref-profile

c:\linhadefensiva\reflist\ref-programfiles

c:\linhadefensiva\reflist\ref-reg

c:\linhadefensiva\reflist\ref-start

c:\linhadefensiva\reflist\ref-startup

c:\linhadefensiva\reflist\ref-sysdrive

c:\linhadefensiva\reflist\ref-system

c:\linhadefensiva\reflist\ref-system32

c:\linhadefensiva\reflist\ref-tasks

c:\linhadefensiva\reflist\ref-temp

c:\linhadefensiva\reflist\ref-wincommon

c:\linhadefensiva\reflist\ref-windows

c:\linhadefensiva\reflist\reft-startup

c:\linhadefensiva\reflist\reg-proxy

c:\linhadefensiva\relatorio.txt

c:\linhadefensiva\relatorios\2009-12-12.txt

c:\linhadefensiva\relatorios\errorlog.txt

c:\linhadefensiva\rotinas\arquiva-relatorio.vbs

c:\linhadefensiva\rotinas\postreboot.bat

c:\linhadefensiva\rotinas\postreboot.vbs

c:\linhadefensiva\rotinas\remocao\driver.vbs

c:\linhadefensiva\rotinas\remocao\shell.vbs

c:\linhadefensiva\rotinas\remocao\userinit.vbs

c:\linhadefensiva\rotinas\remocao\winlogon.vbs

c:\linhadefensiva\rotinas\update.vbs

c:\linhadefensiva\VERSION

c:\windows\system32\EBE27D3236.sys

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_npggsvc

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-11-13 to 2009-12-13 ))))))))))))))))))))))))))))

.

 

2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Malwarebytes

2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Malwarebytes

2009-12-12 23:05 . 2009-12-13 04:53 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat

2009-12-12 22:33 . 2009-12-12 23:05 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Comodo

2009-12-12 22:33 . 2009-12-12 22:33 87104 ----a-w- c:\windows\system32\drivers\inspect.sys

2009-12-12 22:33 . 2009-12-12 22:33 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys

2009-12-12 22:33 . 2009-12-12 22:33 171552 ----a-w- c:\windows\system32\guard32.dll

2009-12-12 22:33 . 2009-12-12 22:33 133064 ----a-w- c:\windows\system32\drivers\cmdguard.sys

2009-12-12 22:33 . 2009-12-12 22:33 -------- d-----w- c:\arquivos de programas\COMODO

2009-12-12 21:36 . 2009-12-13 15:08 -------- d-----w- c:\arquivos de programas\Spybot - Search & Destroy

2009-12-12 21:36 . 2009-12-13 15:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Spybot - Search & Destroy

2009-12-12 21:30 . 2009-12-12 21:30 -------- d-----w- c:\arquivos de programas\CCleaner

2009-12-12 21:05 . 2009-12-12 21:07 707329 ----a-w- C:\Wanasah.exe

2009-12-12 00:37 . 2009-12-12 00:37 53248 ----a-w- c:\windows\fullscreen.exe

2009-12-06 17:33 . 2009-12-06 17:33 -------- d-----w- c:\arquivos de programas\ElfBot NG852

2009-12-05 23:56 . 2009-12-05 23:56 -------- d-----w- c:\windows\system32\LogFiles

2009-12-04 11:31 . 2009-12-04 12:16 -------- d-----w- c:\arquivos de programas\tibiacast2

2009-12-04 11:26 . 2009-11-06 14:49 551936 ----a-w- c:\arquivos de programas\Tibiacast Installer.msi

2009-12-04 11:26 . 2009-12-04 11:23 507461 ----a-w- c:\arquivos de programas\tibiacast_2_6_1.zip

2009-12-03 03:08 . 2009-08-19 07:18 107864 ----a-w- c:\windows\system32\tsccvid.dll

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\windows\system32\QuickTime

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\QuickTime

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\Arquivos comuns\TechSmith Shared

2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\TechSmith

2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Publish Providers

2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Sony

2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Vstplugins

2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Sony

2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Sony

2009-12-03 02:53 . 2009-12-03 02:53 -------- d-----w- c:\arquivos de programas\Sony Setup

2009-12-02 20:54 . 2008-07-08 17:29 1654869 ----a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\DynuEncrypt.dll

2009-12-02 19:30 . 2009-12-02 19:30 -------- d-----w- C:\Level Up! Games

2009-12-02 19:21 . 2009-12-02 19:21 -------- d-----w- C:\TopGames37

2009-12-02 19:18 . 2009-12-02 19:18 -------- d-----w- c:\arquivos de programas\Arquivos comuns\SWF Studio

2009-11-28 13:20 . 2009-11-28 13:21 -------- d-----w- c:\arquivos de programas\TibiaCam TV Lite

2009-11-27 16:07 . 2009-11-27 16:07 -------- d-----w- c:\arquivos de programas\Tibia850

2009-11-26 01:43 . 2009-11-26 01:43 -------- d-----w- c:\arquivos de programas\Gravity

2009-11-26 00:53 . 2009-02-09 05:10 67208 ----a-w- c:\windows\UnDeploy.exe

2009-11-26 00:49 . 2009-11-26 00:50 -------- d-----w- c:\windows\system32\NtmsData

2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Norton

2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Symantec

2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\arquivos de programas\NortonInstaller

2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\NortonInstaller

2009-11-24 19:51 . 2009-11-24 19:51 -------- d-----w- c:\windows\system32\Adobe

2009-11-23 22:34 . 2009-11-23 22:34 -------- d-----w- c:\arquivos de programas\Windows Journal Viewer

2009-11-18 00:43 . 2009-11-18 00:43 190464 ----a-w- c:\windows\system32\delzip179.dll

2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Eng.dll

2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Kor.dll

2009-11-15 22:57 . 2009-09-23 19:42 364912 ----a-w- c:\windows\system32\CMStarterCore.exe

2009-11-15 22:54 . 2009-11-15 22:57 -------- d-----w- c:\arquivos de programas\Webzen

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-13 05:07 . 2009-10-18 20:35 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\TEMP

2009-12-12 22:19 . 2009-09-06 22:27 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Tibia

2009-12-11 13:49 . 2009-09-06 22:26 -------- d-----w- c:\arquivos de programas\Tibia

2009-12-09 23:24 . 2009-10-18 20:34 -------- d-----w- c:\arquivos de programas\ElfBot NG

2009-12-08 22:56 . 2009-09-07 04:33 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center

2009-12-02 19:14 . 2009-09-05 22:28 -------- d-----w- c:\arquivos de programas\microsoft frontpage

2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Media Player Classic

2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack

2009-11-29 16:05 . 2009-09-11 23:43 -------- d-----w- c:\arquivos de programas\Teamspeak2_RC2

2009-11-16 20:58 . 2009-09-07 00:30 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys

2009-11-15 22:57 . 2009-09-05 22:36 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information

2009-11-09 19:29 . 2009-11-09 19:27 -------- d-----w- c:\arquivos de programas\Tibia852

2009-11-09 18:00 . 2009-11-29 20:50 85504 ----a-w- c:\windows\system32\ff_vfw.dll

2009-11-08 22:21 . 2009-11-08 22:10 -------- d-----w- c:\arquivos de programas\No-IP

2009-11-02 13:49 . 2009-11-02 13:49 -------- d-----w- c:\arquivos de programas\Asprate

2009-10-31 22:20 . 2009-09-10 23:36 -------- d-----w- c:\arquivos de programas\TibiaTestserver

2009-10-18 13:34 . 2003-03-30 14:06 76196 ----a-w- c:\windows\system32\perfc016.dat

2009-10-18 13:34 . 2003-03-30 14:06 465632 ----a-w- c:\windows\system32\perfh016.dat

2009-10-06 23:56 . 2009-10-04 01:51 415526 ----a-w- c:\arquivos de programas\backgroung.bmp

.

 

((((((((((((((((((((((((((((( SnapShot@2009-12-13_05.13.41 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-12-13 15:06 . 2009-12-13 15:06 262144 c:\windows\system32\config\systemprofile\NtUser.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]

"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-21 13680640]

"COMODO Internet Security"="c:\arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" [2009-12-12 1800464]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\windows\system32\guard32.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk]

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Microsoft Office.lnk

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2008-10-15 04:04 39792 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2008-06-19 08:20 57344 ----a-r- c:\windows\ALCMTR.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]

2007-08-17 14:50 483144 ----a-w- c:\arquivos de programas\Corel\Corel MediaOne\Corel Photo Downloader.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2004-08-04 03:45 15360 ------w- c:\windows\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-08-04 03:56 1667584 ------w- c:\arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

2009-01-21 16:08 13680640 ----a-w- c:\windows\system32\nvcpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

2009-01-21 16:08 86016 ----a-w- c:\windows\system32\nvmctray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2009-01-21 16:08 1657376 ----a-w- c:\windows\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2008-11-17 08:08 17676288 ----a-r- c:\windows\RTHDCPL.EXE

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Tibia\\Tibia.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"c:\\Arquivos de programas\\Valve\\hl.exe"=

"c:\\Arquivos de programas\\Tibia852\\Tibia.exe"=

"c:\\Arquivos de programas\\Tibia850\\Tibia.exe"=

"c:\\Arquivos de programas\\Tibia\\Tibia2.exe"=

 

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [12/12/2009 20:33 133064]

R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/12/2009 20:33 25160]

S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.terra.com.br/portal/

uInternet Connection Wizard,ShellNext = iexplore

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office10\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=3&q={searchTerms}

FF - prefs.js: browser.startup.homepage - www.google.com

FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=2&q=

FF - component: c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\extensions\{41fe951c-2aaf-4f08-ab67-aebd1ed636f2}\components\FFExternalAlert.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-13 13:17

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(3000)

c:\windows\system32\msi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\PSIService.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-12-13 13:20:04 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-12-13 15:20

ComboFix2.txt 2009-12-13 05:16

 

Pré-execução: 11 pasta(s) 376.268.128.256 bytes disponíveis

Pós execução: 11 pasta(s) 376.163.098.624 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

 

- - End Of File - - 2AB738EDD85BB60880F3C30BB8844A6B

 

 

 

 

E aqui do HijackThis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:20:29, on 13/12/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PSIService.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll

O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

 

--

End of file - 3605 bytes

 

 

Obrigado!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! mukarillo

 

<!> Seus logs não apresentam entradas ruins. :natal_smile:

<><><><><><><><><><><>

<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /uninstall --> Clique OK.

 

< 92674490.jpg >

 

<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )

<@> Clique em Executar --> Aguarde!

<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.

<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!

<@> Ou,vá em Iniciar --> Executar --> Digite ou cole:

 

"%userprofile%\desktop\combofix" /uninstall

 

<@> Clique OK.

<><><><><><><><><><><>

<@> Faça um escaneamento,online,em: < Eset Nod32 >

<@> Utilize o navegador Internet Explorer.

<@> Marque a caixa: "SIM,aceito as condições de uso" --> Iniciar.

<@> Marque a caixa: "YES, I accept the Terms of Use" --> Start.

<@> Aceite a instalação do ActiveX e,ao terminar,salve e poste o relatório. ( C:\Arquivos de programas\EsetOnlineScanner\log )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Prontinho, o log do Eset

 

 

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# IEXPLORE.EXE=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=8a6647a594a37547b073c1f8cc2c43bd

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2009-12-14 03:33:12

# local_time=2009-12-14 01:33:12 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=768 16777215 100 0 8435761 8435761 0 0

# compatibility_mode=1024 16777215 100 0 0 0 0 0

# compatibility_mode=3073 16777189 80 89 0 58868 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=97626

# found=3

# cleaned=3

# scan_time=2444

C:\Wanasah.exe probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C

C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Virtumonde1.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{584F9A72-8980-4029-9F43-668B28870040}\RP67\A0029078.exe probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! mukarillo

 

<@> Baixe: < TFC > ( by Old Timer )

 

<!> Link - 2 < http://www.geekstogo.com/forum/TFC-Temp-File-Cleaner-OldTimer-file187.html >

 

<@> Salve-o no desktop!

<@> Feche todos os programas! ( Internet,navegador,etc... )

<@> Execute TFC.exe,com um duplo-clique.

<@> Ps: Para Windows Vista --> Clique direito --> Escolha: Executar como Administrador

<@> Clique em Start --> Aguarde!

<@> Terminando,reinicie o computador...caso a ferramenta não o solicite e dê início ao processo. ( reboot )

°°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°°

<@> Não havendo problemas,estabeleça um ponto limpo na Restauração do Sistema.

<@> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.

<@> Marque: Desativar Restauração do Sistema --> Aplicar --> Aguarde! --> Ok.

<@> Depois,desmarque novamente! --> Aplicar --> Aguarde! --> Ok.

<@> Para maiores detalhes,leia o Tutorial: < Link >

°°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°°

<!> Seus logs estão limpos! :natal_smile:

<!> Tudo Ok?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.